New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

Summary

cPanel has released a security update to address a critical vulnerability (CVE-2026-58048) that allowed authenticated hosting customers to execute SQL commands with administrative privileges. This flaw enabled a user to bypass privilege boundaries and gain unauthorized access to the server's administrative database identity.

IFF Assessment

FOE

This vulnerability allows unauthorized users to gain administrative privileges on a server, posing a significant threat to data security and system integrity.

Severity

9.4 Critical

The CVSS score of 9.4 indicates a critical severity, reflecting the potential for high impact and ease of exploitation, allowing an authenticated user to gain root access to the database.

Defender Context

This critical vulnerability in cPanel highlights the importance of timely patching for hosting control panels, as such flaws can grant attackers elevated privileges. Defenders should ensure all cPanel instances are updated to the latest security release to mitigate the risk of unauthorized database access and potential data compromise.

Read Full Story →